This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

tool bar and spy?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

One of my kids downloaded "Frostwire" program (reason unknown). That download has included a "Search-Results" toolbar that will not uninstall, even when using their uninstall tools. Additionally, when I go to sign into yahoo mail, there is a security certificate warning and our secure sign-in picture is missing if we choose to bypass the warning.

I have the hikjack this and other download (scans) that have been asked. The Hijack This and the DDS filesa are printed and I have attached the other. Thanks!

Hijack this;
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:13:29 PM, on 7/7/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FYA55AZU\index[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Search-Results Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Search-results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [UVS12 Preload] C:\Program Files (x86)\Corel\Corel VideoStudio 12\uvPL.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [cdloader] "C:\Users\user\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [StartUp This] "C:\Program Files (x86)\Laplink\PCmover\LaunchSt.exe"
O4 - HKCU\..\Run: [UIWatcher] C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe
O4 - HKUS\S-1-5-21-2593354527-203303496-3715345084-1000\..\Run: [cdloader] "C:\Users\user\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - HKUS\S-1-5-21-2593354527-203303496-3715345084-1000\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
O4 - HKUS\S-1-5-21-2593354527-203303496-3715345084-1000\..\Run: [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe (User '?')
O4 - HKUS\S-1-5-21-2593354527-203303496-3715345084-1000\..\Run: [StartUp This] "C:\Program Files (x86)\Laplink\PCmover\LaunchSt.exe" (User '?')
O4 - HKUS\S-1-5-21-2593354527-203303496-3715345084-1000\..\Run: [UIWatcher] C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (User '?')
O4 - S-1-5-21-2593354527-203303496-3715345084-1000 Startup: MemTurbo.lnk = C:\Program Files (x86)\MemTurbo 4\MemTurbo.exe (User '?')
O4 - S-1-5-21-2593354527-203303496-3715345084-1000 Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User '?')
O4 - Startup: MemTurbo.lnk = C:\Program Files (x86)\MemTurbo 4\MemTurbo.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: W311U.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\SysWOW64\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\SysWOW64\msjava.dll (file missing)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BCE045C3-B9B9-40E9-AE06-665877EA1A90}: NameServer = 67.90.152.122,67.107.71.186
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\Windows\SysWow64\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\explorerframe.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\SysWOW64\PSIService.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 10141 bytes

DDS file;

DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 16:05:25.04 on Wed 07/07/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.4095.2113 [GMT -4:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Windows\system32\lsm.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Windows\SysWOW64\PSIService.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MNDMPT30\dds[1].scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.ebay.com/
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mLocal Page = c:\windows\syswow64\blank.htm
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files (x86)\ask.com\GenericAskToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files (x86)\avg\avg9\avgssie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Search-results Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files (x86)\ask.com\GenericAskToolbar.dll
TB: Search-results Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files (x86)\ask.com\GenericAskToolbar.dll
uRun: [cdloader] "c:\users\user\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [Messenger (Yahoo!)] "c:\progra~2\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files (x86)\yahoo!\search protection\SearchProtection.exe
uRun: [StartUp This] "c:\program files (x86)\laplink\pcmover\LaunchSt.exe"
uRun: [UIWatcher] c:\program files (x86)\ashampoo\ashampoo uninstaller 3\UIWatcher.exe
mRun: [UVS12 Preload] c:\program files (x86)\corel\corel videostudio 12\uvPL.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AVG9_TRAY] c:\progra~2\avg\avg9\avgtray.exe
StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\memturbo.lnk - c:\program files (x86)\memturbo 4\MemTurbo.exe
StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files (x86)\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\w311u.lnk - c:\program files (x86)\tenda\w311u\UI.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\syswow64\msjava.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14-windows-i586.cab
DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {BCE045C3-B9B9-40E9-AE06-665877EA1A90} = 67.90.152.122,67.107.71.186
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files (x86)\avg\avg9\avgpp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll
mASetup: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - c:\windows\syswow64\ieudinit.exe
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files (x86)\avg\avg9\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll
BHO-X64: Windows Live Family Safety Browser Helper - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
AppInit_DLLs-X64: avgrssta.dll
IFEO-X64: Your Image File Name Here without a path - ntsd -d

================= FIREFOX ===================

FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\5fcf805o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Search-Results
FF - prefs.js: browser.startup.homepage - hxxp://www.search-results.com?o=16077&l=dis
FF - prefs.js: keyword.URL - hxxp://websearch.search-results.com/redirect?client=ff&src=kw&tb=FW-SRS&o=16074&locale=en_US&apn_uid=13B6DCA1-F081-404D-A50B-D569DCACD8EF&apn_ptnrs=OC&apn_sauid=2C633A0A-8D8B-4564-8C98-A2E607B421C9&apn_dtid=YYYYYYS4US&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 7212
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files (x86)\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files (x86)\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files (x86)\java\j2re1.4.1\bin\NPJPI141.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-6-24 69152]
R1 AvgLdx64;AVG Free AVI Loader Driver x64;c:\windows\system32\drivers\avgldx64.sys [2010-6-15 269320]
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;c:\windows\system32\drivers\avgmfx64.sys [2010-6-15 35536]
R1 AvgTdiA;AVG Free Network Redirector x64;c:\windows\system32\drivers\avgtdia.sys [2010-6-15 317520]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 203264]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files (x86)\avg\avg9\avgemc.exe [2010-6-15 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files (x86)\avg\avg9\avgwdsvc.exe [2010-6-15 308064]
R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\netr28ux.sys [2010-7-3 982016]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-6-10 187392]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 17920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\lavasoft\ad-aware\AAWService.exe [2010-2-4 1352832]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-5-22 61288]
S3 fsssvc;Windows Live Family Safety Service;c:\program files (x86)\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-20 1255736]

=============== Created Last 30 ================

2010-07-04 00:39:49 30208 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-07-04 00:39:45 982016 —-a-w- c:\windows\system32\drivers\netr28ux.sys
2010-07-04 00:39:45 305152 —-a-w- c:\windows\system32\RaCoInstx.dll
2010-07-04 00:39:45 13931 —-a-w- c:\windows\system32\RaCoInst.dat
2010-07-04 00:39:41 0 d—–w- c:\program files (x86)\Tenda
2010-06-24 07:22:36 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-06-24 06:06:46 69152 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-24 06:06:43 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-24 06:01:34 0 dc-h–w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-06-24 06:01:24 0 d—–w- c:\program files (x86)\Lavasoft
2010-06-23 07:00:55 99176 —-a-w- c:\windows\syswow64\PresentationHostProxy.dll
2010-06-23 07:00:55 49472 —-a-w- c:\windows\syswow64\netfxperf.dll
2010-06-23 07:00:55 48960 —-a-w- c:\windows\system32\netfxperf.dll
2010-06-23 07:00:55 444752 —-a-w- c:\windows\system32\mscoree.dll
2010-06-23 07:00:55 320352 —-a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 07:00:55 297808 —-a-w- c:\windows\syswow64\mscoree.dll
2010-06-23 07:00:55 295264 —-a-w- c:\windows\syswow64\PresentationHost.exe
2010-06-23 07:00:55 1942856 —-a-w- c:\windows\system32\dfshim.dll
2010-06-23 07:00:55 1130824 —-a-w- c:\windows\syswow64\dfshim.dll
2010-06-23 07:00:55 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-22 17:56:42 1736608 —-a-w- c:\windows\system32\ntdll.dll
2010-06-22 17:56:42 1289528 —-a-w- c:\windows\syswow64\ntdll.dll
2010-06-22 17:56:20 961024 —-a-w- c:\windows\system32\CPFilters.dll
2010-06-22 17:56:20 641536 —-a-w- c:\windows\syswow64\CPFilters.dll
2010-06-22 17:56:20 552960 —-a-w- c:\windows\system32\msdri.dll
2010-06-22 17:56:20 288256 —-a-w- c:\windows\system32\MSNP.ax
2010-06-22 17:56:20 258560 —-a-w- c:\windows\system32\mpg2splt.ax
2010-06-22 17:56:20 204288 —-a-w- c:\windows\syswow64\MSNP.ax
2010-06-22 17:56:20 199680 —-a-w- c:\windows\syswow64\mpg2splt.ax
2010-06-20 03:50:04 14 —-a-w- c:\windows\ASSE.dat
2010-06-20 03:36:17 0 d—–w- c:\program files (x86)\MemTurbo 4
2010-06-19 05:07:37 0 d—–w- c:\programdata\Spybot - Search & Destroy
2010-06-19 05:07:37 0 d—–w- c:\program files (x86)\Spybot - Search & Destroy
2010-06-15 11:08:49 0 d–h–w- C:\$AVG
2010-06-15 06:06:08 12976 —-a-w- c:\windows\system32\avgrssta.dll
2010-06-15 06:06:06 317520 —-a-w- c:\windows\system32\drivers\avgtdia.sys
2010-06-15 06:06:01 269320 —-a-w- c:\windows\system32\drivers\avgldx64.sys
2010-06-15 06:05:59 35536 —-a-w- c:\windows\system32\drivers\avgmfx64.sys
2010-06-15 06:05:59 0 d—–w- c:\windows\system32\drivers\Avg
2010-06-15 06:04:02 0 d—–w- c:\program files (x86)\AVG
2010-06-15 06:03:51 0 d—–w- c:\programdata\avg9

==================== Find3M ====================

2010-05-27 07:24:13 34304 —-a-w- c:\windows\syswow64\atmlib.dll
2010-05-27 06:34:09 46080 —-a-w- c:\windows\system32\atmlib.dll
2010-05-27 04:11:32 366080 —-a-w- c:\windows\system32\atmfd.dll
2010-05-27 03:49:37 293888 —-a-w- c:\windows\syswow64\atmfd.dll
2010-05-21 18:14:28 270208 ——w- c:\windows\system32\MpSigStub.exe
2010-05-21 05:52:30 1192960 —-a-w- c:\windows\system32\wininet.dll
2010-05-21 05:18:06 977920 —-a-w- c:\windows\syswow64\wininet.dll
2010-05-21 05:14:50 48128 —-a-w- c:\windows\syswow64\jsproxy.dll
2010-05-06 12:42:05 1225216 —-a-w- c:\windows\syswow64\urlmon.dll
2010-05-06 12:41:55 606208 —-a-w- c:\windows\syswow64\mstime.dll
2010-05-06 12:41:53 64512 —-a-w- c:\windows\syswow64\msfeedsbs.dll
2010-05-06 12:41:53 5970944 —-a-w- c:\windows\syswow64\mshtml.dll
2010-05-06 12:41:49 381440 —-a-w- c:\windows\syswow64\iedkcs32.dll
2010-05-06 12:41:49 10984448 —-a-w- c:\windows\syswow64\ieframe.dll
2010-05-01 15:07:05 3122176 —-a-w- c:\windows\system32\win32k.sys
2010-04-23 07:13:36 2048 —-a-w- c:\windows\syswow64\tzres.dll
2010-04-23 07:11:58 2048 —-a-w- c:\windows\system32\tzres.dll
2010-04-20 00:57:31 72080 —-a-w- c:\users\user\g2mdlhlpx.exe
2010-04-17 04:04:40 306032 —-a-w- c:\windows\WLXPGSS.SCR
2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-07-02 03:21:18 200 —-a-w- c:\program files (x86)\INSTALL.LOG
2008-08-16 16:50:08 28336456 —-a-w- c:\program files (x86)\UVS11.5PatchEng.exe
2008-08-16 16:42:19 144572944 —-a-w- c:\program files (x86)\uleadvideostudio11plus.exe
2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2010-03-05 14:51:52 245760 –sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-02-24 11:20:58 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 16:05:44.15 ===============

Attachments:

Hi


Please do the following:

  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Programs And Features
  • Remove the following program:

"Ask Toolbar"

then do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Search-Results Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Search-results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.



NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
There wasn't and "ask" toolbar. I did fing the "Search-results toolbar" which is the one that loaded with the "Frostwire" download that my son did. I went through the process trying to remove that toolbar. A window opened that said I needed to close all windows programs to complete the uninstall. So I did. The result was that nothing happened, then the same window reappeared giving the same info despite the fact that there weren't any application open. The only option to get that window to disappear was to "cancel" which brought me back to the same situation. I did not re-run the hjk as nothing changed, the toolbar did not uninstall and is still in the mainwindow.
Try Revo Uninstaller:


Download and install the Revo Uninstaller
  • Double click the new Revo Uninstaller icon on your desktop to start the program
  • Scroll through the listed programs and Right Click on the program you wish to uninstall
  • From the pop out menu choose Uninstall
  • Click Yes to the confirmation dialogue
  • In the next window select the Advanced mode
  • Click Next to start uninstalling the program
  • Answer Yes to confirm the uninstall
  • When the program has completed the four steps, click Next to allow the program to search for leftovers
  • Once complete, click Next, then Finish
  • Repeat the above steps for any other programs you wish to remove.
This is kinda interesting, when I loaded the Revo tool I found the "Ask Toolbar" as you had orignally suggested…however, that toolbar is not installed. Using Revo uninstaller and folllowing the isntructions simply installed the real "Ask Toolbar" which I then uninstalled - the "Search-results" toolbar was there also (things were gettin' crowded).

When I go through control panel to do a traditional uninstall, there is no "Ask Toolbar" but there is the "Search-results Toolbar" which, as I already explained, will not uninstall itself. I did a little research on this toolbar, within its own information area (the "About" section) I found this information…the toolbar calls itself the "Qbyrd Toolbar" and it has a FAQ section, part of which is;

What is the Qbyrd Toolbar?

The Qbyrd Toolbar is a free browser add-on that allows you to search the Web using the Qbyrd search engine directly from Internet Explorer or Firefox browsers.


I also have an uninstall program from Ashampoo which I also tried to use to remove this toolbar. The result was the same as with Revo, the "Search-results Toolbar" never populated the list, but the "Ask Toolbar" certainly did, though it was not installed.

So, I have still not run a hjt report, but will if you need. The toolbar in question is still intact.
No

Please run this tool instead:



Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Only the one document showed, copied and pasted here:

OTL logfile created on: 7/12/2010 11:49:28 PM - Run 3
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\user\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.76 Gb Total Space | 382.94 Gb Free Space | 82.22% Space Free | Partition Type: NTFS
Drive D: | 232.79 Gb Total Space | 232.53 Gb Free Space | 99.89% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 59.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-PC
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\user\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\user\AppData\Roaming\mjusbsp\magicJack.exe (magicJack L.P.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Tenda\W311U\UI.exe ()
PRC - C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
PRC - C:\Windows\SysWOW64\PSIService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\user\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (StorSvc) – C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (fsssvc) – C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ProtexisLicensing) – C:\Windows\SysWOW64\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/http://www.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 75 80 62 C6 F3 B4 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Search-Results"
FF - prefs.js..browser.search.defaultenginename: "Search-Results"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.order.1: "Search-Results"
FF - prefs.js..browser.search.selectedEngine: "Search-Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.search-results.com?o=16077&l;=dis"
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {d57c9ff1-6389-48fc-b770-f78bd89b6e8a}:1.33
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: {75623d5d-4683-402a-b610-ac4bab767c86}:3.0.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.7.1.11118
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - prefs.js..keyword.URL: "http://websearch.search-results.com/redirect?client=ff&src;=kw&tb;=FW-SRS&o;=16074&locale;=en_US&apn;_uid=13B6DCA1-F081-404D-A50B-D569DCACD8EF&apn;_ptnrs=OC&apn;_sauid=2C633A0A-8D8B-4564-8C98-A2E607B421C9&apn;_dtid=YYYYYYS4US&q;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 7212
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.socks_version: 4
FF - prefs.js..network.proxy.type: 4


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/06/15 20:13:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/02 23:46:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/04 07:05:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.2\extensions\\Components: C:\Program Files (x86)\SeaMonkey\components [2010/04/16 20:40:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.2\extensions\\Plugins: C:\Program Files (x86)\SeaMonkey\plugins [2010/04/21 00:18:49 | 000,000,000 | —D | M]

[2010/05/03 00:27:36 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Extensions
[2010/03/06 06:53:59 | 000,000,000 | —D | M] (No name found) – C:\Users\user\AppData\Roaming\mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2010/03/06 06:53:59 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Extensions\[removed]
[2010/03/06 06:53:59 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Extensions\[removed]
[2010/07/07 21:53:29 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions
[2010/05/03 00:44:44 | 000,000,000 | —D | M] (NoScript) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/06 06:40:56 | 000,000,000 | —D | M] (Surf Canyon - Search Engine Assistant) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
[2010/05/03 00:44:44 | 000,000,000 | —D | M] (No name found) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/05/03 00:44:44 | 000,000,000 | —D | M] (No name found) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}
[2010/05/06 06:40:57 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\morningCoffee@shaneliesegang
[2010/03/06 06:54:05 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\[removed]
[2010/03/06 06:54:05 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\TEMP
[2010/07/03 21:38:35 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\[removed]
[2010/03/06 06:54:17 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\SeaMonkey\Profiles\9fpwbte0.default\extensions
[2008/11/22 15:37:32 | 000,001,733 | —- | M] () – C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\live-search.xml
[2010/07/03 21:38:35 | 000,003,358 | —- | M] () – C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\search-results.xml
[2010/06/07 11:33:25 | 000,002,282 | —- | M] () – C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\surf-canyon.xml
[2010/07/07 21:53:29 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search-results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKLM\..\Toolbar: (Search-results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKCU\..\Toolbar\WebBrowser: (Search-results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [UVS12 Preload] C:\Program Files (x86)\Corel\Corel VideoStudio 12\uvPL.exe (Corel TW Corp.)
O4 - HKCU..\Run: [cdloader] C:\Users\user\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe File not found
O4 - HKCU..\Run: [StartUp This] C:\Program Files (x86)\Laplink\PCmover\LaunchSt.exe (Laplink Software, Inc.)
O4 - HKCU..\Run: [UIWatcher] C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MemTurbo.lnk = C:\Program Files (x86)\MemTurbo 4\MemTurbo.exe (SammSoft (www.sammsoft.com))
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\SysWOW64\msjava.dll File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab (Java Plug-in 1.4.1)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab (Java Plug-in 1.4.1)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\ExplorerFrame.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/25 20:48:46 | 000,000,047 | R— | M] () - F:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{6558522f-5f6e-11df-8094-00e04d9ed95e}\Shell - "" = AutoRun
O33 - MountPoints2\{6558522f-5f6e-11df-8094-00e04d9ed95e}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{e99badd4-190c-11df-ab81-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e99badd4-190c-11df-ab81-806e6f6e6963}\Shell\AutoRun\command - "" = F:\W311U.exe – [2009/09/11 07:18:14 | 002,156,480 | R— | M] ()
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\autorun.exe – File not found
O33 - MountPoints2\I\Shell\phone\command - "" = I:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.iyuv - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.uyvy - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yuy2 - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yvyu - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.dvacm - C:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.MPEGacm - C:\Program Files (x86)\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.ulmp3acm - C:\Program Files (x86)\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.vp60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 90 Days ==========

[2010/07/12 23:18:43 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\user\Desktop\OTL.exe
[2010/07/11 23:10:28 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\VS Revo Group
[2010/07/11 23:10:25 | 000,031,800 | —- | C] (VS Revo Group) – C:\Windows\SysNative\drivers\revoflt.sys
[2010/07/11 23:10:24 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/07/03 20:39:45 | 000,982,016 | —- | C] (Ralink Technology Corp.) – C:\Windows\SysNative\drivers\netr28ux.sys
[2010/07/03 20:39:45 | 000,305,152 | —- | C] (Ralink Technology, Inc.) – C:\Windows\SysNative\RaCoInstx.dll
[2010/07/03 20:39:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tenda
[2010/07/03 20:39:11 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\InstallShield
[2010/06/26 03:01:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/06/24 02:06:46 | 000,069,152 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/06/24 02:06:43 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2010/06/24 02:01:34 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/06/24 02:01:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010/06/21 08:25:34 | 000,000,000 | R-SD | C] – C:\Users\user\Documents\My Stationery
[2010/06/19 23:36:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\MemTurbo 4
[2010/06/19 01:07:37 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/06/19 01:07:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/06/15 09:08:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\avg
[2010/06/15 07:08:49 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/06/15 02:06:08 | 000,012,976 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/06/15 02:06:06 | 000,317,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/06/15 02:06:01 | 000,269,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/06/15 02:05:59 | 000,035,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/06/15 02:05:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010/06/15 02:04:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/06/15 02:03:51 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/06/11 00:12:56 | 000,000,000 | —D | C] – C:\Users\user\Desktop\200 Internet Marketing Articles
[2010/05/31 08:32:30 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\DivX
[2010/05/28 20:50:14 | 000,000,000 | —D | C] – C:\Users\user\Desktop\Kimberly
[2010/05/26 21:37:32 | 000,000,000 | —D | C] – C:\Windows\SysWow64\custom matrices
[2010/05/26 21:37:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\C2MP
[2010/05/26 21:37:29 | 000,000,000 | —D | C] – C:\Windows\SysWow64\QuickTime
[2010/05/26 21:37:29 | 000,000,000 | —D | C] – C:\Windows\SysWow64\C2MP
[2010/05/22 11:45:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2010/05/22 11:44:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/05/22 11:44:54 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/05/22 11:43:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010/05/22 11:43:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010/05/22 11:43:01 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010/05/22 11:42:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010/05/22 11:42:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010/05/22 11:32:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2010/05/13 01:32:35 | 000,000,000 | —D | C] – C:\Users\user\Documents\Word Wizard Results
[2010/05/06 21:51:10 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\Wordpress Mage
[2010/05/06 21:50:22 | 000,000,000 | —D | C] – C:\Program Files Wordpress Mage
[2010/05/03 00:27:46 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\Google
[2010/05/02 16:56:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\FileZilla FTP Client
[2010/04/29 00:05:04 | 000,000,000 | —D | C] – C:\Users\user\Documents\CustomBrowser[1]
[2010/04/26 21:56:47 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2010/04/25 12:40:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\AKVIS
[2010/04/24 17:59:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Traffic Hybrid Software
[2010/04/23 22:59:40 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\Affilorama
[2010/04/23 22:59:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Traffic Travis v3
[2010/04/23 21:46:14 | 000,000,000 | —D | C] – C:\Users\user\Desktop\Web Success
[2010/04/22 21:28:42 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\ElevatedDiagnostics
[2010/04/21 20:25:43 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\TweetGlide.4C2CA0B91861599E32033FE57CA969D1117C4915.1
[2010/04/21 20:25:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\TweetGlide
[2010/04/20 00:49:19 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/04/20 00:49:18 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/04/19 20:58:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Citrix
[2010/04/19 20:57:15 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\Deployment
[2010/04/16 21:22:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\SDA
[2010/04/16 14:55:27 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\AskToolbar
[2010/04/16 14:53:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2010/04/16 14:34:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
[2010/04/16 14:33:01 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/15 23:56:15 | 000,000,000 | —D | C] – C:\Program Files\MozyHome
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/07/12 23:50:12 | 006,291,456 | -HS- | M] () – C:\Users\user\ntuser.dat
[2010/07/12 23:18:21 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\user\Desktop\OTL.exe
[2010/07/12 23:01:34 | 000,081,754 | —- | M] () – C:\Users\user\Desktop\4a.jpg
[2010/07/12 23:01:13 | 000,075,403 | —- | M] () – C:\Users\user\Desktop\1a.jpg
[2010/07/12 23:00:24 | 000,076,103 | —- | M] () – C:\Users\user\Desktop\5.jpg
[2010/07/12 23:00:11 | 000,081,379 | —- | M] () – C:\Users\user\Desktop\4.jpg
[2010/07/12 22:59:58 | 000,083,205 | —- | M] () – C:\Users\user\Desktop\3.jpg
[2010/07/12 22:59:43 | 000,084,079 | —- | M] () – C:\Users\user\Desktop\2.jpg
[2010/07/12 22:59:26 | 000,078,582 | —- | M] () – C:\Users\user\Desktop\1.jpg
[2010/07/12 18:42:50 | 061,925,743 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/12 16:19:47 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/12 16:19:47 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/12 16:19:47 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/12 10:19:33 | 000,013,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/12 10:19:33 | 000,013,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/12 10:15:31 | 000,001,015 | —- | M] () – C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MemTurbo.lnk
[2010/07/12 10:15:27 | 000,000,987 | —- | M] () – C:\Users\user\Desktop\magicJack.lnk
[2010/07/12 10:12:13 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/12 10:12:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/12 10:11:57 | 3220,676,608 | -HS- | M] () – C:\hiberfil.sys
[2010/07/12 09:44:41 | 000,074,845 | —- | M] () – C:\Users\user\Desktop\r4.jpg
[2010/07/12 09:44:37 | 000,076,103 | —- | M] () – C:\Users\user\Desktop\r3.jpg
[2010/07/12 09:44:29 | 000,083,205 | —- | M] () – C:\Users\user\Desktop\r2.jpg
[2010/07/12 09:38:31 | 000,109,158 | —- | M] () – C:\Users\user\Desktop\r1.jpg
[2010/07/12 09:37:27 | 000,101,300 | —- | M] () – C:\Users\user\Desktop\r5.jpg
[2010/07/11 23:10:25 | 000,000,973 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2010/07/11 10:04:13 | 004,078,425 | -H– | M] () – C:\Users\user\AppData\Local\IconCache.db
[2010/07/10 02:48:36 | 000,065,103 | —- | M] () – C:\Users\user\Desktop\Zero_2_Hero_Secret_Budget_Guide.pdf
[2010/07/06 15:28:01 | 000,073,878 | —- | M] () – C:\Users\user\Desktop\Paystub__from_Nautix_Lifegu.pdf
[2010/07/03 21:56:51 | 000,001,004 | -HS- | M] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2010/07/03 21:25:59 | 000,000,297 | —- | M] () – C:\Users\user\Desktop\Autorun - Shortcut.lnk
[2010/07/03 20:44:27 | 000,001,001 | —- | M] () – C:\Users\user\AppData\Local\RT2870_{177327C7-17E3-4129-BE5D-682CDC6089E5}_wsc
[2010/07/03 20:39:43 | 000,000,786 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\W311U.lnk
[2010/07/03 20:39:43 | 000,000,768 | —- | M] () – C:\Users\Public\Desktop\W311U.lnk
[2010/07/02 19:02:00 | 000,079,849 | —- | M] () – C:\Users\user\Desktop\34265_460697390967_794325967_6067988_1265616_n.jpg
[2010/07/02 09:18:45 | 000,068,798 | —- | M] () – C:\Users\user\Desktop\luka.jpg
[2010/07/02 07:56:36 | 000,130,265 | —- | M] () – C:\Users\user\Desktop\senior zach.jpg
[2010/07/02 07:53:55 | 000,130,136 | —- | M] () – C:\Users\user\Desktop\senior luke.jpg
[2010/07/01 21:53:09 | 000,010,752 | —- | M] () – C:\Users\user\Desktop\Hammers Sit.xls
[2010/07/01 19:53:41 | 000,027,176 | —- | M] () – C:\Users\user\Desktop\34236_462848525967_794325967_6125791_618428_n.jpg
[2010/06/30 22:24:25 | 000,023,661 | —- | M] () – C:\Users\user\Desktop\nitrofill.odt
[2010/06/30 21:33:02 | 000,016,037 | —- | M] () – C:\Users\user\Desktop\Suite Upgrades.odt
[2010/06/30 16:50:13 | 000,013,447 | —- | M] () – C:\Users\user\Desktop\BEACH.ods
[2010/06/29 07:39:30 | 000,021,336 | —- | M] () – C:\Users\user\Desktop\Navigator Contact.ods
[2010/06/24 02:06:42 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2010/06/24 02:06:37 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010/06/24 02:06:03 | 000,069,152 | —- | M] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/06/24 02:01:31 | 000,001,166 | —- | M] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/06/23 20:24:33 | 000,018,890 | —- | M] () – C:\Users\user\Desktop\nissan ac.odt
[2010/06/19 23:50:04 | 000,000,014 | —- | M] () – C:\Windows\ASSE.dat
[2010/06/19 23:36:17 | 000,000,977 | —- | M] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\MemTurbo - PC Optimizer.lnk
[2010/06/15 12:46:51 | 000,164,864 | —- | M] () – C:\Users\user\Desktop\Law Schools Data.xls
[2010/06/15 09:08:41 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/06/15 09:08:41 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/06/15 02:06:09 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/06/15 02:06:08 | 000,012,976 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/06/15 02:06:01 | 000,269,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/06/15 02:05:59 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/06/12 03:19:05 | 000,463,616 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/05/13 00:57:51 | 000,001,033 | —- | M] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/05/02 23:46:54 | 000,001,939 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/19 20:57:31 | 000,072,080 | —- | M] () – C:\Users\user\g2mdlhlpx.exe
[2010/04/17 03:17:35 | 000,524,288 | -HS- | M] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000002.regtrans-ms
[2010/04/17 03:17:35 | 000,524,288 | -HS- | M] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000001.regtrans-ms
[2010/04/17 03:17:35 | 000,065,536 | -HS- | M] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TM.blf
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/12 23:01:52 | 000,081,754 | —- | C] () – C:\Users\user\Desktop\4a.jpg
[2010/07/12 23:01:30 | 000,075,403 | —- | C] () – C:\Users\user\Desktop\1a.jpg
[2010/07/12 23:00:30 | 000,076,103 | —- | C] () – C:\Users\user\Desktop\5.jpg
[2010/07/12 23:00:19 | 000,081,379 | —- | C] () – C:\Users\user\Desktop\4.jpg
[2010/07/12 23:00:07 | 000,083,205 | —- | C] () – C:\Users\user\Desktop\3.jpg
[2010/07/12 22:59:54 | 000,084,079 | —- | C] () – C:\Users\user\Desktop\2.jpg
[2010/07/12 22:59:40 | 000,078,582 | —- | C] () – C:\Users\user\Desktop\1.jpg
[2010/07/12 09:57:41 | 000,101,300 | —- | C] () – C:\Users\user\Desktop\r5.jpg
[2010/07/12 09:55:46 | 000,074,845 | —- | C] () – C:\Users\user\Desktop\r4.jpg
[2010/07/12 09:55:15 | 000,076,103 | —- | C] () – C:\Users\user\Desktop\r3.jpg
[2010/07/12 09:54:25 | 000,109,158 | —- | C] () – C:\Users\user\Desktop\r1.jpg
[2010/07/12 09:53:45 | 000,083,205 | —- | C] () – C:\Users\user\Desktop\r2.jpg
[2010/07/11 23:10:25 | 000,000,973 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2010/07/10 02:48:36 | 000,065,103 | —- | C] () – C:\Users\user\Desktop\Zero_2_Hero_Secret_Budget_Guide.pdf
[2010/07/06 15:28:03 | 000,073,878 | —- | C] () – C:\Users\user\Desktop\Paystub__from_Nautix_Lifegu.pdf
[2010/07/03 21:25:59 | 000,000,297 | —- | C] () – C:\Users\user\Desktop\Autorun - Shortcut.lnk
[2010/07/03 20:41:42 | 000,001,001 | —- | C] () – C:\Users\user\AppData\Local\RT2870_{177327C7-17E3-4129-BE5D-682CDC6089E5}_wsc
[2010/07/03 20:39:45 | 000,013,931 | —- | C] () – C:\Windows\SysNative\RaCoInst.dat
[2010/07/03 20:39:43 | 000,000,786 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\W311U.lnk
[2010/07/03 20:39:43 | 000,000,768 | —- | C] () – C:\Users\Public\Desktop\W311U.lnk
[2010/07/02 19:02:10 | 000,079,849 | —- | C] () – C:\Users\user\Desktop\34265_460697390967_794325967_6067988_1265616_n.jpg
[2010/07/02 09:19:25 | 000,068,798 | —- | C] () – C:\Users\user\Desktop\luka.jpg
[2010/07/02 07:59:57 | 000,130,136 | —- | C] () – C:\Users\user\Desktop\senior luke.jpg
[2010/07/02 07:58:50 | 000,130,265 | —- | C] () – C:\Users\user\Desktop\senior zach.jpg
[2010/07/01 21:53:05 | 000,010,752 | —- | C] () – C:\Users\user\Desktop\Hammers Sit.xls
[2010/07/01 19:52:00 | 000,027,176 | —- | C] () – C:\Users\user\Desktop\34236_462848525967_794325967_6125791_618428_n.jpg
[2010/06/30 22:24:23 | 000,023,661 | —- | C] () – C:\Users\user\Desktop\nitrofill.odt
[2010/06/30 17:06:57 | 000,016,037 | —- | C] () – C:\Users\user\Desktop\Suite Upgrades.odt
[2010/06/30 07:50:41 | 000,013,447 | —- | C] () – C:\Users\user\Desktop\BEACH.ods
[2010/06/28 22:58:48 | 000,021,336 | —- | C] () – C:\Users\user\Desktop\Navigator Contact.ods
[2010/06/24 03:22:36 | 000,015,880 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2010/06/24 02:01:31 | 000,001,166 | —- | C] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/06/23 20:24:31 | 000,018,890 | —- | C] () – C:\Users\user\Desktop\nissan ac.odt
[2010/06/19 23:50:04 | 000,000,014 | —- | C] () – C:\Windows\ASSE.dat
[2010/06/19 23:36:17 | 000,001,015 | —- | C] () – C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MemTurbo.lnk
[2010/06/19 23:36:17 | 000,000,977 | —- | C] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\MemTurbo - PC Optimizer.lnk
[2010/06/15 12:46:49 | 000,164,864 | —- | C] () – C:\Users\user\Desktop\Law Schools Data.xls
[2010/06/15 02:06:09 | 000,001,854 | —- | C] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/06/15 02:05:59 | 061,925,743 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/06/15 02:05:59 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/05/02 23:46:54 | 000,001,939 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/04/16 20:42:54 | 000,524,288 | -HS- | C] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000002.regtrans-ms
[2010/04/16 20:42:54 | 000,524,288 | -HS- | C] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000001.regtrans-ms
[2010/04/16 20:42:54 | 000,065,536 | -HS- | C] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TM.blf
[2010/03/16 14:10:32 | 000,001,004 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2010/03/02 20:00:00 | 004,555,278 | —- | C] () – C:\Windows\SysWow64\libavcodec.dll
[2010/03/02 20:00:00 | 001,449,935 | —- | C] () – C:\Windows\SysWow64\ffmpegmt.dll
[2010/03/02 20:00:00 | 000,882,688 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/03/02 20:00:00 | 000,877,385 | —- | C] () – C:\Windows\SysWow64\ff_x264.dll
[2010/03/02 20:00:00 | 000,556,491 | —- | C] () – C:\Windows\SysWow64\libmplayer.dll
[2010/03/02 20:00:00 | 000,336,384 | —- | C] () – C:\Windows\SysWow64\ff_libfaad2.dll
[2010/03/02 20:00:00 | 000,324,096 | —- | C] () – C:\Windows\SysWow64\TomsMoComp_ff.dll
[2010/03/02 20:00:00 | 000,248,320 | —- | C] () – C:\Windows\SysWow64\ff_kernelDeint.dll
[2010/03/02 20:00:00 | 000,216,576 | —- | C] () – C:\Windows\SysWow64\ff_libdts.dll
[2010/03/02 20:00:00 | 000,169,984 | —- | C] () – C:\Windows\SysWow64\ff_samplerate.dll
[2010/03/02 20:00:00 | 000,151,552 | —- | C] () – C:\Windows\SysWow64\ff_libmad.dll
[2010/03/02 20:00:00 | 000,145,408 | —- | C] () – C:\Windows\SysWow64\libmpeg2_ff.dll
[2010/03/02 20:00:00 | 000,121,856 | —- | C] () – C:\Windows\SysWow64\ff_liba52.dll
[2010/03/02 20:00:00 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\ff_tremor.dll
[2010/03/02 20:00:00 | 000,100,864 | —- | C] () – C:\Windows\SysWow64\ff_wmv9.dll
[2010/03/02 20:00:00 | 000,097,792 | —- | C] () – C:\Windows\SysWow64\ff_unrar.dll
[2010/03/02 20:00:00 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/02/13 17:55:48 | 000,209,040 | —- | C] () – C:\Windows\SysWow64\IVIresizeW7.dll
[2010/02/13 17:55:48 | 000,204,944 | —- | C] () – C:\Windows\SysWow64\IVIresizeA6.dll
[2010/02/13 17:55:48 | 000,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeP6.dll
[2010/02/13 17:55:48 | 000,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeM6.dll
[2010/02/13 17:55:48 | 000,192,656 | —- | C] () – C:\Windows\SysWow64\IVIresizePX.dll
[2010/02/13 17:55:48 | 000,024,720 | —- | C] () – C:\Windows\SysWow64\IVIresize.dll
[2009/11/14 14:37:08 | 000,154,112 | —- | C] () – C:\Windows\SysWow64\ts.dll
[2009/11/14 14:33:38 | 000,249,856 | —- | C] () – C:\Windows\SysWow64\dxr.dll
[2009/11/14 14:11:50 | 000,093,184 | —- | C] () – C:\Windows\SysWow64\avss.dll
[2009/11/14 14:11:42 | 000,150,016 | —- | C] () – C:\Windows\SysWow64\mkx.dll
[2009/11/14 14:11:42 | 000,141,824 | —- | C] () – C:\Windows\SysWow64\mp4.dll
[2009/11/14 14:11:40 | 000,123,392 | —- | C] () – C:\Windows\SysWow64\ogm.dll
[2009/11/14 14:11:40 | 000,109,568 | —- | C] () – C:\Windows\SysWow64\avi.dll
[2009/11/14 14:11:38 | 000,097,792 | —- | C] () – C:\Windows\SysWow64\avs.dll
[2009/11/14 14:11:32 | 000,080,384 | —- | C] () – C:\Windows\SysWow64\mkzlib.dll
[2009/11/14 14:11:32 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\mkunicode.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/07 12:24:04 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/01/10 18:15:44 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\mmfinfo.dll
[2008/11/06 12:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2007/12/18 22:12:42 | 000,000,000 | —- | C] () – C:\Windows\PTWebCam.INI
[2007/12/04 10:02:30 | 000,000,171 | —- | C] () – C:\Windows\QUICKEN.INI
[2007/10/13 05:30:20 | 000,000,137 | —- | C] () – C:\Windows\SysWow64\Registration.ini
[2005/11/14 19:01:24 | 000,000,030 | —- | C] () – C:\Windows\congo.ini
[2005/11/04 14:39:39 | 000,000,185 | —- | C] () – C:\Windows\32bitfax.ini
[2005/11/04 14:05:37 | 000,000,534 | —- | C] () – C:\Windows\faxmailn.ini
[2005/11/03 22:14:58 | 000,000,109 | —- | C] () – C:\Windows\MBEDIT16.INI
[2005/11/03 21:59:56 | 000,000,455 | —- | C] () – C:\Windows\mathb16.ini
[2005/11/03 21:59:48 | 000,000,000 | —- | C] () – C:\Windows\rkeeper.ini
[2005/11/03 21:56:03 | 000,000,000 | —- | C] () – C:\Windows\autorun.INI
[2005/01/14 12:48:21 | 000,003,451 | —- | C] () – C:\Windows\32bifax.ini
[2005/01/03 23:07:01 | 000,000,000 | —- | C] () – C:\Windows\iPlayer.INI
[2004/12/28 01:55:50 | 000,374,784 | —- | C] () – C:\Windows\3dg32.dll
[2004/12/28 01:55:47 | 000,000,250 | —- | C] () – C:\Windows\3dr.ini
[2004/12/26 15:38:15 | 000,000,177 | —- | C] () – C:\Windows\kpcms.ini
[2004/12/26 13:59:25 | 000,000,002 | —- | C] () – C:\Windows\PhotoSuite.ini
[2004/12/18 23:29:40 | 000,000,026 | —- | C] () – C:\Windows\Load.INI
[2004/12/18 23:04:54 | 000,000,015 | —- | C] () – C:\Windows\campaignsave.INI
[2004/12/05 15:51:55 | 000,004,795 | —- | C] () – C:\Windows\cdplayer.ini
[2004/11/19 21:15:38 | 000,000,019 | —- | C] () – C:\Windows\KNP.INI
[2004/10/31 23:30:39 | 000,000,754 | —- | C] () – C:\Windows\WORDPAD.INI
[2004/10/04 20:27:02 | 000,000,287 | —- | C] () – C:\Windows\SIERRA.INI
[2004/09/27 18:30:02 | 000,000,057 | —- | C] () – C:\Windows\picturific.ini
[2004/07/13 19:00:59 | 000,000,061 | —- | C] () – C:\Windows\smscfg.ini

========== LOP Check ==========

[2010/04/23 22:59:40 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Affilorama
[2010/03/06 06:52:08 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Aim
[2010/03/06 06:52:26 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Ashampoo
[2010/03/06 06:52:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\BellSouth
[2010/03/06 06:52:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/03/06 06:52:35 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\DMCache
[2010/03/06 06:52:35 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\eFax Messenger
[2010/03/06 06:52:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\HighKey
[2010/03/06 06:52:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\InterTrust
[2010/03/06 06:52:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\j2 Global
[2010/03/06 06:52:44 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Leadertech
[2010/03/06 06:52:44 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\LG Electronics
[2010/03/06 06:53:44 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2010/07/12 10:15:30 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mjusbsp
[2010/03/06 06:54:30 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\MP3Rocket
[2010/03/06 06:54:36 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\MSNInstaller
[2010/02/24 14:23:37 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\OpenOffice.org
[2010/03/06 06:54:55 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Research In Motion
[2010/03/06 06:55:40 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\SanDisk
[2010/03/06 06:55:47 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\SmartDraw
[2010/03/06 06:55:49 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\SoftMaker
[2010/03/06 01:49:13 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Spearit
[2010/03/06 06:56:42 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Template
[2010/03/06 06:56:42 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Tenebril
[2010/04/21 20:25:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\TweetGlide.4C2CA0B91861599E32033FE57CA969D1117C4915.1
[2010/03/06 06:56:42 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Ulead Systems
[2010/03/06 06:56:56 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\uTorrent
[2010/03/06 06:56:57 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Viewpoint
[2010/03/06 06:57:20 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\WeatherBug
[2010/03/06 06:57:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\wootalyzer
[2010/03/06 06:57:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\ZipGenius
[2009/07/14 01:08:49 | 000,026,342 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/12/18 22:11:28 | 000,000,035 | —- | M] () – C:\aa.txt
[2009/11/05 23:28:24 | 000,000,863 | —- | M] () – C:\ashampoo-acdw-log.txt
[2007/11/07 21:20:58 | 000,024,086 | —- | M] () – C:\ASLog.txt
[2004/12/18 22:26:50 | 003,205,124 | RHS- | M] () – C:\AVG6DB_F.DAT
[2004/11/04 23:32:01 | 000,004,122 | —- | M] () – C:\avgun.log
[2004/11/04 23:33:12 | 000,000,207 | —- | M] () – C:\Boot.bak
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/02/03 23:48:51 | 000,017,883 | —- | M] () – C:\ComboFix.txt
[2007/08/29 18:51:49 | 000,000,035 | —- | M] () – C:\CommMgr.log
[2005/11/14 18:44:07 | 000,000,000 | —- | M] () – C:\CONFIG.BKA
[2007/04/09 22:54:13 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2006/06/26 02:36:16 | 000,000,004 | -HS- | M] () – C:\dllimp_regmsft985
[2006/08/05 22:18:32 | 000,000,113 | —- | M] () – C:\DownloadLog.txt
[2007/04/30 15:39:39 | 000,000,000 | —- | M] () – C:\Encoder.log
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 12:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 12:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 12:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 12:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2009/05/14 14:05:55 | 000,530,083 | —- | M] (BellSouth Internet Services ) – C:\HC4DecommissionScheduler.exe
[2010/07/12 10:11:57 | 3220,676,608 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 12:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 12:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/10/05 15:11:56 | 000,000,395 | —- | M] () – C:\INSTALL.LOG
[2009/12/04 01:22:03 | 000,000,000 | —- | M] () – C:\install.rdf
[2007/11/07 12:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 12:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 12:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 12:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 12:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 12:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 12:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 12:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 12:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/12/02 22:08:00 | 000,000,517 | —- | M] () – C:\lxbt.log
[2010/05/13 00:57:52 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2006/12/02 03:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2007/11/01 06:08:14 | 000,001,145 | —- | M] () – C:\net_save.dna
[2004/11/03 12:44:36 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/01/22 08:55:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2009/06/03 01:04:47 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2009/06/03 01:04:47 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2010/07/12 10:12:01 | 4294,238,208 | -HS- | M] () – C:\pagefile.sys
[2009/02/03 08:24:20 | 000,002,286 | —- | M] () – C:\rapport.txt
[2009/10/19 01:40:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/11/18 21:26:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/11/25 16:43:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2005/04/21 07:06:22 | 000,000,018 | —- | M] () – C:\SYSREST
[2008/10/30 19:14:51 | 000,000,510 | —- | M] () – C:\updatedatfix.log
[2007/11/07 12:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 12:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/07 12:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI
[2007/04/13 19:28:32 | 000,000,150 | —- | M] () – C:\YServer.txt
[2 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 21:15:13 | 000,346,112 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\dxtmsft.dll
[2009/07/13 21:15:13 | 000,215,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\dxtrans.dll
[2009/07/13 21:15:28 | 000,186,368 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\iepeers.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\user32.dll /md5 >
[2009/07/13 21:11:24 | 000,833,024 | —- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 – C:\Windows\SysWOW64\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2009/07/13 21:16:20 | 000,206,336 | —- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D – C:\Windows\SysWOW64\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2009/07/13 21:11:26 | 000,004,608 | —- | M] (Microsoft Corporation) MD5=808AABDF9337312195CAFF76D1804786 – C:\Windows\SysWOW64\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
    FF - prefs.js..extensions.enabledItems: [removed]:3.7.1.11118
    [2010/07/03 21:38:35 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\[removed]
    O2 - BHO: (Search-results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
    O3 - HKLM\..\Toolbar: (Search-results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
    O3 - HKCU\..\Toolbar\WebBrowser: (Search-results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Search-Results)
    [2010/04/16 14:55:27 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\AskToolbar
    [2010/04/16 14:34:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
    [2010/07/03 21:38:35 | 000,003,358 | —- | M] () – C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\search-results.xml
    FF - prefs.js..browser.search.defaultengine: "Search-Results"
    FF - prefs.js..browser.search.defaultenginename: "Search-Results"
    FF - prefs.js..browser.search.order.1: "Search-Results"
    FF - prefs.js..browser.search.selectedEngine: "Search-Results"
    FF - prefs.js..browser.startup.homepage: "http://www.search-results.com?o=16077&l=dis"
    FF - prefs.js..keyword.URL: "http://websearch.search-results.com/redirect?client=ff&src=kw&tb=FW-SRS&o=16074&locale=en_US&apn_uid=13B6DCA1-F081-404D-A50B-D569DCACD8EF&apn_ptnrs=OC&apn_sauid=2C633A0A-8D8B-4564-8C98-A2E607B421C9&apn_dtid=YYYYYYS4US&q="
    FF - prefs.js..network.proxy.http_port: 7212
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log
I left the settings on minimal output and I did not have either of the two boxes checked (LOP or Purity). The program stopped responding. I reset it, pasted in the commands…it starts but stops responding after about 4 minutes…
I am inputting the code just as entered above; copied from and including the" :OTL thru [reboot] " but in the safe mode, the program goes into non-response almost immediately and I have to manually close the program while it is hung up.
Hi

we'll have to try deleting this manually then, I've never known this toolbar to be this stubborn

please reset IE and FireFox, to uninstall the add-ons in the browsers:

1. Open Internet Explorer 8.
2. Click Tools from the Command Bar and select Internet Options.
3. Select the Advanced tab.
4. Go to the Reset Internet Explorer settings section and click the Reset button.

5. You will then see a window that outlines the impact of resetting IE8. A basic reset will disable toolbars and add-ons, and reset default web browser settings, advanced options, tabbed browsing settings, privacy settings, pop-up settings and security settings.
If you check the Delete personal settings checkbox, it will reset the home page(s), search providers and Accelerators to their default values. It will also delete the temp internet files, history, cookies, passwords and InPrivate Blocking data.

When you have it set to reset the desired information, click the Reset button.


Now reset FireFox

Access the FireFox “Safe Mode”

Press the WinKey + R to open a run box

Copy/Paste the following into the open run box then click “OK”

firefox -safe-mode

Once you have started Firefox in “Safe Mode”, you will see a window with the following choices:
  • Disable all add-ons – all extensions and themes will be turned off while in safe mode
  • Reset toolbars and controls – removes any changes or customization that you have made to the toolbar(s)
  • Reset bookmarks to Firefox defaults – removes your current set of bookmarks and resets to the original default set of bookmarks
  • Reset all user preferences to Firefox defaults – restores the options, preference settings, and the theme back to the original default settings (Note: This will also reset all the entries in about:config back to their original default settings and remove any custom entries that you have added.)
  • Restore default search engines – restores all of the original default search engines (based on the language version you have installed) without removing any of the search engines that you may have installed/added

Select all the options except your bookmarks if you wish to keep them.
Once selected, click “Make Changes and Restart”.


NEXT


Try this batch file:


  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off
    if exist results.txt del results.txt
    reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}" /f >> results.txt 2>>&1
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{00000000-6E41-4FD3-8538-502F5495E5FC}" /f  >> results.txt 2>>&1
    reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{D4027C7F-154A-4066-A1AD-4243D8127440}" /f  >> results.txt 2>>&1
    reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{D4027C7F-154A-4066-A1AD-4243D8127440}" /f  >> results.txt 2>>&1
    FOR %%H IN (
    "C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll"
    "C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\[removed]"
    "C:\Program Files (x86)\Ask.com"
    "C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\search-results.xml"
    ) DO (
    attrib -r -h -s %%H
    del /q /f %%H >> results.txt 2>>&1
    )
    rmdir /S /Q "C:\Users\user\AppData\Local\AskToolbar"  >> results.txt 2>>&1
    del %0
  • Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click fix.bat. to run it. A small black box should open and close - this is normal.
  • Please post the content of results.txt
Everything worked as anticipated. Here are the results; ERROR: The system was unable to find the specified registry key or value. ERROR: The system was unable to find the specified registry key or value. ERROR: The system was unable to find the specified registry key or value. The operation completed successfully. Could Not Find C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll Could Not Find C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\[removed] C:\Program Files (x86)\Ask.com\btn_search.png Access is denied. C:\Program Files (x86)\Ask.com\cobrand.ico Access is denied. C:\Program Files (x86)\Ask.com\config.xml Access is denied. C:\Program Files (x86)\Ask.com\favicon.ico Access is denied. C:\Program Files (x86)\Ask.com\fv_7d09.ico Access is denied. C:\Program Files (x86)\Ask.com\limewire_logo.png Access is denied. C:\Program Files (x86)\Ask.com\mupcfg.xml Access is denied. C:\Program Files (x86)\Ask.com\SaUpdate.exe Access is denied. C:\Program Files (x86)\Ask.com\UpdateTask.exe Access is denied.
Boot into Safe mode:

Reboot and tap F8 repeatedly till an advanced option menu appears > arrow up to safe mode

Now navigate to C:\Program Files (x86)\Ask.com > right click and delete that folder

If you find any other folders relating to ASK > right click and delete them.

Please post a fresh OTL log so I can see what remains
OTL logfile created on: 7/14/2010 8:35:38 AM - Run 5
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\user\Desktop\Miscellaneous Storage
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 68.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.76 Gb Total Space | 382.22 Gb Free Space | 82.06% Space Free | Partition Type: NTFS
Drive D: | 232.79 Gb Total Space | 232.53 Gb Free Space | 99.89% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 59.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-PC
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\user\Desktop\Miscellaneous Storage\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\user\AppData\Roaming\mjusbsp\st00000\mjsetup.exe (magicJack L.P.)
PRC - C:\Users\user\AppData\Roaming\mjusbsp\magicJack.exe (magicJack L.P.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
PRC - C:\Windows\SysWOW64\PSIService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\user\Desktop\Miscellaneous Storage\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (StorSvc) – C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (fsssvc) – C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ProtexisLicensing) – C:\Windows\SysWOW64\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/http://www.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========



FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/06/15 20:13:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/02 23:46:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/13 20:25:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.2\extensions\\Components: C:\Program Files (x86)\SeaMonkey\components [2010/04/16 20:40:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.2\extensions\\Plugins: C:\Program Files (x86)\SeaMonkey\plugins [2010/07/13 20:25:12 | 000,000,000 | —D | M]

[2010/05/03 00:27:36 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Extensions
[2010/03/06 06:53:59 | 000,000,000 | —D | M] (No name found) – C:\Users\user\AppData\Roaming\mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2010/03/06 06:53:59 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Extensions\[removed]
[2010/03/06 06:53:59 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Extensions\[removed]
[2010/07/14 00:23:04 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions
[2010/05/03 00:44:44 | 000,000,000 | —D | M] (NoScript) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/06 06:40:56 | 000,000,000 | —D | M] (Surf Canyon - Search Engine Assistant) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
[2010/05/03 00:44:44 | 000,000,000 | —D | M] (No name found) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/05/03 00:44:44 | 000,000,000 | —D | M] (No name found) – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}
[2010/05/06 06:40:57 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\morningCoffee@shaneliesegang
[2010/03/06 06:54:05 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\[removed]
[2010/03/06 06:54:05 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\5fcf805o.default\extensions\TEMP
[2010/03/06 06:54:17 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mozilla\SeaMonkey\Profiles\9fpwbte0.default\extensions
[2008/11/22 15:37:32 | 000,001,733 | —- | M] () – C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\live-search.xml
[2010/06/07 11:33:25 | 000,002,282 | —- | M] () – C:\Users\user\AppData\Roaming\Mozilla\FireFox\Profiles\5fcf805o.default\searchplugins\surf-canyon.xml
[2010/07/07 21:53:29 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [UVS12 Preload] C:\Program Files (x86)\Corel\Corel VideoStudio 12\uvPL.exe (Corel TW Corp.)
O4 - HKCU..\Run: [cdloader] C:\Users\user\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe File not found
O4 - HKCU..\Run: [StartUp This] C:\Program Files (x86)\Laplink\PCmover\LaunchSt.exe (Laplink Software, Inc.)
O4 - HKCU..\Run: [UIWatcher] C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MemTurbo.lnk = C:\Program Files (x86)\MemTurbo 4\MemTurbo.exe (SammSoft (www.sammsoft.com))
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\SysWOW64\msjava.dll File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab (Java Plug-in 1.4.1)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab (Java Plug-in 1.4.1)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\ExplorerFrame.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/25 20:48:46 | 000,000,047 | R— | M] () - F:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{6558522f-5f6e-11df-8094-00e04d9ed95e}\Shell - "" = AutoRun
O33 - MountPoints2\{6558522f-5f6e-11df-8094-00e04d9ed95e}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{e99badd4-190c-11df-ab81-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e99badd4-190c-11df-ab81-806e6f6e6963}\Shell\AutoRun\command - "" = F:\W311U.exe – [2009/09/11 07:18:14 | 002,156,480 | R— | M] ()
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\autorun.exe – File not found
O33 - MountPoints2\I\Shell\phone\command - "" = I:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/07/13 20:25:06 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/07/13 01:34:14 | 000,000,000 | —D | C] – C:\_OTL
[2010/07/13 00:14:13 | 000,000,000 | —D | C] – C:\Users\user\Desktop\Hammers baseball
[2010/07/13 00:07:17 | 000,000,000 | —D | C] – C:\Users\user\Desktop\Zach
[2010/07/11 23:10:28 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\VS Revo Group
[2010/07/11 23:10:25 | 000,031,800 | —- | C] (VS Revo Group) – C:\Windows\SysNative\drivers\revoflt.sys
[2010/07/11 23:10:24 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/07/03 20:39:45 | 000,982,016 | —- | C] (Ralink Technology Corp.) – C:\Windows\SysNative\drivers\netr28ux.sys
[2010/07/03 20:39:45 | 000,305,152 | —- | C] (Ralink Technology, Inc.) – C:\Windows\SysNative\RaCoInstx.dll
[2010/07/03 20:39:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tenda
[2010/07/03 20:39:11 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\InstallShield
[2010/06/26 03:01:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/06/24 02:06:46 | 000,069,152 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/06/24 02:06:43 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2010/06/24 02:01:34 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/06/24 02:01:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010/06/21 08:25:34 | 000,000,000 | R-SD | C] – C:\Users\user\Documents\My Stationery
[2010/06/19 23:36:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\MemTurbo 4
[2010/06/19 01:07:37 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/06/19 01:07:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/06/15 09:08:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\avg
[2010/06/15 07:08:49 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/06/15 02:06:08 | 000,012,976 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/06/15 02:06:06 | 000,317,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/06/15 02:06:01 | 000,269,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/06/15 02:05:59 | 000,035,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/06/15 02:05:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010/06/15 02:04:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/06/15 02:03:51 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/05/31 08:32:30 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\DivX
[2010/05/26 21:37:32 | 000,000,000 | —D | C] – C:\Windows\SysWow64\custom matrices
[2010/05/26 21:37:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\C2MP
[2010/05/26 21:37:29 | 000,000,000 | —D | C] – C:\Windows\SysWow64\QuickTime
[2010/05/26 21:37:29 | 000,000,000 | —D | C] – C:\Windows\SysWow64\C2MP
[2010/05/22 11:45:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2010/05/22 11:44:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/05/22 11:44:54 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/05/22 11:43:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010/05/22 11:43:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010/05/22 11:43:01 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010/05/22 11:42:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010/05/22 11:42:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010/05/22 11:32:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2010/05/13 01:32:35 | 000,000,000 | —D | C] – C:\Users\user\Documents\Word Wizard Results
[2010/05/06 21:51:10 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\Wordpress Mage
[2010/05/06 21:50:22 | 000,000,000 | —D | C] – C:\Program Files Wordpress Mage
[2010/05/03 00:27:46 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\Google
[2010/05/02 16:56:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\FileZilla FTP Client
[2010/04/29 00:05:04 | 000,000,000 | —D | C] – C:\Users\user\Documents\CustomBrowser[1]
[2010/04/26 21:56:47 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2010/04/25 12:40:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\AKVIS
[2010/04/24 17:59:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Traffic Hybrid Software
[2010/04/23 22:59:40 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\Affilorama
[2010/04/23 22:59:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Traffic Travis v3
[2010/04/23 21:46:14 | 000,000,000 | —D | C] – C:\Users\user\Desktop\Web Success
[2010/04/22 21:28:42 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\ElevatedDiagnostics
[2010/04/21 20:25:43 | 000,000,000 | —D | C] – C:\Users\user\AppData\Roaming\TweetGlide.4C2CA0B91861599E32033FE57CA969D1117C4915.1
[2010/04/21 20:25:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\TweetGlide
[2010/04/20 00:49:19 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/04/20 00:49:18 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/04/19 20:58:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Citrix
[2010/04/19 20:57:15 | 000,000,000 | —D | C] – C:\Users\user\AppData\Local\Deployment
[2010/04/16 21:22:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\SDA
[2010/04/16 14:53:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2010/04/16 14:33:01 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/15 23:56:15 | 000,000,000 | —D | C] – C:\Program Files\MozyHome
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/07/14 08:34:23 | 000,000,394 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/07/14 08:34:12 | 000,000,987 | —- | M] () – C:\Users\user\Desktop\magicJack.lnk
[2010/07/14 08:34:06 | 000,001,015 | —- | M] () – C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MemTurbo.lnk
[2010/07/14 08:33:05 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/14 08:32:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/14 08:32:53 | 3220,676,608 | -HS- | M] () – C:\hiberfil.sys
[2010/07/14 08:32:15 | 006,291,456 | -HS- | M] () – C:\Users\user\ntuser.dat
[2010/07/14 08:27:56 | 000,013,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/14 08:27:55 | 000,013,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/14 00:20:54 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/14 00:20:54 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/14 00:20:54 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/13 17:38:56 | 061,961,059 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/03 21:56:51 | 000,001,004 | -HS- | M] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2010/07/03 20:44:27 | 000,001,001 | —- | M] () – C:\Users\user\AppData\Local\RT2870_{177327C7-17E3-4129-BE5D-682CDC6089E5}_wsc
[2010/07/03 20:39:43 | 000,000,786 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\W311U.lnk
[2010/07/02 07:56:36 | 000,130,265 | —- | M] () – C:\Users\user\Desktop\senior zach.jpg
[2010/07/02 07:53:55 | 000,130,136 | —- | M] () – C:\Users\user\Desktop\senior luke.jpg
[2010/06/30 21:33:02 | 000,016,037 | —- | M] () – C:\Users\user\Desktop\Suite Upgrades.odt
[2010/06/29 07:39:30 | 000,021,336 | —- | M] () – C:\Users\user\Desktop\Navigator Contact.ods
[2010/06/24 02:06:42 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2010/06/24 02:06:37 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010/06/24 02:06:03 | 000,069,152 | —- | M] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/06/24 02:01:31 | 000,001,166 | —- | M] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/06/23 20:24:33 | 000,018,890 | —- | M] () – C:\Users\user\Desktop\nissan ac.odt
[2010/06/19 23:50:04 | 000,000,014 | —- | M] () – C:\Windows\ASSE.dat
[2010/06/19 23:36:17 | 000,000,977 | —- | M] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\MemTurbo - PC Optimizer.lnk
[2010/06/15 12:46:51 | 000,164,864 | —- | M] () – C:\Users\user\Desktop\Law Schools Data.xls
[2010/06/15 09:08:41 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/06/15 09:08:41 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/06/15 02:06:08 | 000,012,976 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/06/15 02:06:01 | 000,269,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/06/15 02:05:59 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/06/12 03:19:05 | 000,463,616 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/05/13 00:57:51 | 000,001,033 | —- | M] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/05/02 23:46:54 | 000,001,939 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/19 20:57:31 | 000,072,080 | —- | M] () – C:\Users\user\g2mdlhlpx.exe
[2010/04/17 03:17:35 | 000,524,288 | -HS- | M] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000002.regtrans-ms
[2010/04/17 03:17:35 | 000,524,288 | -HS- | M] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000001.regtrans-ms
[2010/04/17 03:17:35 | 000,065,536 | -HS- | M] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TM.blf
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/14 08:29:43 | 000,000,394 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/07/03 20:41:42 | 000,001,001 | —- | C] () – C:\Users\user\AppData\Local\RT2870_{177327C7-17E3-4129-BE5D-682CDC6089E5}_wsc
[2010/07/03 20:39:45 | 000,013,931 | —- | C] () – C:\Windows\SysNative\RaCoInst.dat
[2010/07/03 20:39:43 | 000,000,786 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\W311U.lnk
[2010/07/02 07:59:57 | 000,130,136 | —- | C] () – C:\Users\user\Desktop\senior luke.jpg
[2010/07/02 07:58:50 | 000,130,265 | —- | C] () – C:\Users\user\Desktop\senior zach.jpg
[2010/06/30 17:06:57 | 000,016,037 | —- | C] () – C:\Users\user\Desktop\Suite Upgrades.odt
[2010/06/28 22:58:48 | 000,021,336 | —- | C] () – C:\Users\user\Desktop\Navigator Contact.ods
[2010/06/24 03:22:36 | 000,015,880 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2010/06/24 02:01:31 | 000,001,166 | —- | C] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/06/23 20:24:31 | 000,018,890 | —- | C] () – C:\Users\user\Desktop\nissan ac.odt
[2010/06/19 23:50:04 | 000,000,014 | —- | C] () – C:\Windows\ASSE.dat
[2010/06/19 23:36:17 | 000,001,015 | —- | C] () – C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MemTurbo.lnk
[2010/06/19 23:36:17 | 000,000,977 | —- | C] () – C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\MemTurbo - PC Optimizer.lnk
[2010/06/15 12:46:49 | 000,164,864 | —- | C] () – C:\Users\user\Desktop\Law Schools Data.xls
[2010/06/15 02:05:59 | 061,961,059 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/06/15 02:05:59 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/05/02 23:46:54 | 000,001,939 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/04/16 20:42:54 | 000,524,288 | -HS- | C] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000002.regtrans-ms
[2010/04/16 20:42:54 | 000,524,288 | -HS- | C] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TMContainer00000000000000000001.regtrans-ms
[2010/04/16 20:42:54 | 000,065,536 | -HS- | C] () – C:\Users\user\ntuser.dat{7bdb4c96-49ac-11df-b60b-00e04d9ed95e}.TM.blf
[2010/03/16 14:10:32 | 000,001,004 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2010/03/02 20:00:00 | 004,555,278 | —- | C] () – C:\Windows\SysWow64\libavcodec.dll
[2010/03/02 20:00:00 | 001,449,935 | —- | C] () – C:\Windows\SysWow64\ffmpegmt.dll
[2010/03/02 20:00:00 | 000,882,688 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/03/02 20:00:00 | 000,877,385 | —- | C] () – C:\Windows\SysWow64\ff_x264.dll
[2010/03/02 20:00:00 | 000,556,491 | —- | C] () – C:\Windows\SysWow64\libmplayer.dll
[2010/03/02 20:00:00 | 000,336,384 | —- | C] () – C:\Windows\SysWow64\ff_libfaad2.dll
[2010/03/02 20:00:00 | 000,324,096 | —- | C] () – C:\Windows\SysWow64\TomsMoComp_ff.dll
[2010/03/02 20:00:00 | 000,248,320 | —- | C] () – C:\Windows\SysWow64\ff_kernelDeint.dll
[2010/03/02 20:00:00 | 000,216,576 | —- | C] () – C:\Windows\SysWow64\ff_libdts.dll
[2010/03/02 20:00:00 | 000,169,984 | —- | C] () – C:\Windows\SysWow64\ff_samplerate.dll
[2010/03/02 20:00:00 | 000,151,552 | —- | C] () – C:\Windows\SysWow64\ff_libmad.dll
[2010/03/02 20:00:00 | 000,145,408 | —- | C] () – C:\Windows\SysWow64\libmpeg2_ff.dll
[2010/03/02 20:00:00 | 000,121,856 | —- | C] () – C:\Windows\SysWow64\ff_liba52.dll
[2010/03/02 20:00:00 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\ff_tremor.dll
[2010/03/02 20:00:00 | 000,100,864 | —- | C] () – C:\Windows\SysWow64\ff_wmv9.dll
[2010/03/02 20:00:00 | 000,097,792 | —- | C] () – C:\Windows\SysWow64\ff_unrar.dll
[2010/03/02 20:00:00 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/02/13 17:55:48 | 000,209,040 | —- | C] () – C:\Windows\SysWow64\IVIresizeW7.dll
[2010/02/13 17:55:48 | 000,204,944 | —- | C] () – C:\Windows\SysWow64\IVIresizeA6.dll
[2010/02/13 17:55:48 | 000,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeP6.dll
[2010/02/13 17:55:48 | 000,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeM6.dll
[2010/02/13 17:55:48 | 000,192,656 | —- | C] () – C:\Windows\SysWow64\IVIresizePX.dll
[2010/02/13 17:55:48 | 000,024,720 | —- | C] () – C:\Windows\SysWow64\IVIresize.dll
[2009/11/14 14:37:08 | 000,154,112 | —- | C] () – C:\Windows\SysWow64\ts.dll
[2009/11/14 14:33:38 | 000,249,856 | —- | C] () – C:\Windows\SysWow64\dxr.dll
[2009/11/14 14:11:50 | 000,093,184 | —- | C] () – C:\Windows\SysWow64\avss.dll
[2009/11/14 14:11:42 | 000,150,016 | —- | C] () – C:\Windows\SysWow64\mkx.dll
[2009/11/14 14:11:42 | 000,141,824 | —- | C] () – C:\Windows\SysWow64\mp4.dll
[2009/11/14 14:11:40 | 000,123,392 | —- | C] () – C:\Windows\SysWow64\ogm.dll
[2009/11/14 14:11:40 | 000,109,568 | —- | C] () – C:\Windows\SysWow64\avi.dll
[2009/11/14 14:11:38 | 000,097,792 | —- | C] () – C:\Windows\SysWow64\avs.dll
[2009/11/14 14:11:32 | 000,080,384 | —- | C] () – C:\Windows\SysWow64\mkzlib.dll
[2009/11/14 14:11:32 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\mkunicode.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/07 12:24:04 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/01/10 18:15:44 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\mmfinfo.dll
[2008/11/06 12:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2007/12/18 22:12:42 | 000,000,000 | —- | C] () – C:\Windows\PTWebCam.INI
[2007/12/04 10:02:30 | 000,000,171 | —- | C] () – C:\Windows\QUICKEN.INI
[2007/10/13 05:30:20 | 000,000,137 | —- | C] () – C:\Windows\SysWow64\Registration.ini
[2005/11/14 19:01:24 | 000,000,030 | —- | C] () – C:\Windows\congo.ini
[2005/11/04 14:39:39 | 000,000,185 | —- | C] () – C:\Windows\32bitfax.ini
[2005/11/04 14:05:37 | 000,000,534 | —- | C] () – C:\Windows\faxmailn.ini
[2005/11/03 22:14:58 | 000,000,109 | —- | C] () – C:\Windows\MBEDIT16.INI
[2005/11/03 21:59:56 | 000,000,455 | —- | C] () – C:\Windows\mathb16.ini
[2005/11/03 21:59:48 | 000,000,000 | —- | C] () – C:\Windows\rkeeper.ini
[2005/11/03 21:56:03 | 000,000,000 | —- | C] () – C:\Windows\autorun.INI
[2005/01/14 12:48:21 | 000,003,451 | —- | C] () – C:\Windows\32bifax.ini
[2005/01/03 23:07:01 | 000,000,000 | —- | C] () – C:\Windows\iPlayer.INI
[2004/12/28 01:55:50 | 000,374,784 | —- | C] () – C:\Windows\3dg32.dll
[2004/12/28 01:55:47 | 000,000,250 | —- | C] () – C:\Windows\3dr.ini
[2004/12/26 15:38:15 | 000,000,177 | —- | C] () – C:\Windows\kpcms.ini
[2004/12/26 13:59:25 | 000,000,002 | —- | C] () – C:\Windows\PhotoSuite.ini
[2004/12/18 23:29:40 | 000,000,026 | —- | C] () – C:\Windows\Load.INI
[2004/12/18 23:04:54 | 000,000,015 | —- | C] () – C:\Windows\campaignsave.INI
[2004/12/05 15:51:55 | 000,004,795 | —- | C] () – C:\Windows\cdplayer.ini
[2004/11/19 21:15:38 | 000,000,019 | —- | C] () – C:\Windows\KNP.INI
[2004/10/31 23:30:39 | 000,000,754 | —- | C] () – C:\Windows\WORDPAD.INI
[2004/10/04 20:27:02 | 000,000,287 | —- | C] () – C:\Windows\SIERRA.INI
[2004/09/27 18:30:02 | 000,000,057 | —- | C] () – C:\Windows\picturific.ini
[2004/07/13 19:00:59 | 000,000,061 | —- | C] () – C:\Windows\smscfg.ini

========== LOP Check ==========

[2010/04/23 22:59:40 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Affilorama
[2010/03/06 06:52:08 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Aim
[2010/03/06 06:52:26 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Ashampoo
[2010/03/06 06:52:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\BellSouth
[2010/03/06 06:52:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/03/06 06:52:35 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\DMCache
[2010/03/06 06:52:35 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\eFax Messenger
[2010/03/06 06:52:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\HighKey
[2010/03/06 06:52:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\InterTrust
[2010/03/06 06:52:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\j2 Global
[2010/03/06 06:52:44 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Leadertech
[2010/03/06 06:52:44 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\LG Electronics
[2010/03/06 06:53:44 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2010/07/14 08:34:28 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\mjusbsp
[2010/03/06 06:54:30 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\MP3Rocket
[2010/03/06 06:54:36 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\MSNInstaller
[2010/02/24 14:23:37 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\OpenOffice.org
[2010/03/06 06:54:55 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Research In Motion
[2010/03/06 06:55:40 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\SanDisk
[2010/03/06 06:55:47 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\SmartDraw
[2010/03/06 06:55:49 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\SoftMaker
[2010/03/06 01:49:13 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Spearit
[2010/03/06 06:56:42 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Template
[2010/03/06 06:56:42 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Tenebril
[2010/04/21 20:25:43 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\TweetGlide.4C2CA0B91861599E32033FE57CA969D1117C4915.1
[2010/03/06 06:56:42 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Ulead Systems
[2010/03/06 06:56:56 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\uTorrent
[2010/03/06 06:56:57 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\Viewpoint
[2010/03/06 06:57:20 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\WeatherBug
[2010/03/06 06:57:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\wootalyzer
[2010/03/06 06:57:27 | 000,000,000 | —D | M] – C:\Users\user\AppData\Roaming\ZipGenius
[2010/07/14 08:34:23 | 000,000,394 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/14 01:08:49 | 000,027,594 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI